{"id":15118,"date":"2021-11-04T18:20:13","date_gmt":"2021-11-04T22:20:13","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=15118"},"modified":"2024-03-20T15:55:11","modified_gmt":"2024-03-20T19:55:11","slug":"what-is-a-key-management-service-key-management-services-explained","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/what-is-a-key-management-service-key-management-services-explained\/","title":{"rendered":"What Is a Key Management Service? Key Management Services Explained"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-a-lost-or-stolen-cryptographic-key-can-devastate-a-company-that-s-why-many-companies-choose-to-use-key-management-services-to-protect-and-secure-their-organization-s-sensitive-assets\">A lost or stolen cryptographic key can devastate a company \u2014 that\u2019s why many companies choose to use key management services to protect and secure their organization\u2019s sensitive assets<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When you\u2019re out and about, there\u2019s virtually no worse feeling than reaching into your pocket or purse and discovering that your keys are missing. The realization hits you like a ton of bricks, and you\u2019re left asking two important questions: <em>where did you leave them? And what happens if someone untrustworthy finds your keys before you do?<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Your keys are your literal method of access to important places in your life \u2014 your home, office, and your car. Keys keep bad guys out yet enable you access to everything you hold dear. Needless to say, you don\u2019t want them winding up in the wrong hands! The same can be said about your organization\u2019s cryptographic keys. These sensitive keys do everything from secure your website and email communications to authenticate users and devices on your network. Therefore, you need to keep them safe from compromise and do everything you can to mitigate risks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.keyfactor.com\/resources\/the-impact-of-unsecured-digital-identities-2020-report-critical-trust-index\/\">Keyfactor and the Ponemon Institute research<\/a> shows that organizations report having an average of 88,750 digital keys and certificates within their IT environments. And to make matters worse, 74% of respondents indicate they don\u2019t actually know how many keys actually exist or where to find them! As you can imagine, this level of oversight can cause irreparable harm if you\u2019re one of these businesses. Having a key management service in place can be a lifesaver (or, more accurately, a job saver).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This article will explore what a key management service is and why it\u2019s a crucial investment for your organization.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-a-key-management-service-a-kms-definition\">What Is a Key Management Service? A KMS Definition<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A <strong>key management service<\/strong> (KMS) is a system for securely storing, managing, and backing up cryptographic keys. Of course, the specific types of keys that each KMS supports vary from one platform to another. Most key management services typically allow you to manage one or more of the following secrets:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>SSL certificate private keys<\/li>\n\n\n\n<li>SSH key pairs<\/li>\n\n\n\n<li>API keys<\/li>\n\n\n\n<li>Code signing private keys<\/li>\n\n\n\n<li>Document signing private keys<\/li>\n\n\n\n<li>Database encryption keys<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Key management services are designed to help you avoid a key being lost or stolen (which could result in a data breach, downtime, or data loss). Features vary a bit between different solutions, but most key management services include at least these capabilities:<\/p>\n\n\n\n<ol class=\"wp-block-list\" style=\"list-style-type:1\">\n<li>Web-based interface for managing your cryptographic keys.<\/li>\n\n\n\n<li>Secure storage and backup of private keys (typically on a hardware security module, or HSM \u2014 we&#8217;ll speak more to that in a bit).<\/li>\n\n\n\n<li>APIs and\/or plugins to integrate the KMS with your servers, software, and systems.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-kms-vs-kms-vs-kmass\">KMS vs KMS vs KMasS<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Key management services, <a href=\"https:\/\/www.thesslstore.com\/blog\/the-ultimate-guide-to-key-management-systems\/\">key management systems<\/a> and key management-as-a-service (KMaaS) are three terms that often refer to the same thing. While there are some technical differences, these terms are often used interchangeably to refer to systems (usually cloud based) for managing cryptographic keys.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">(Remember how we\u2019ve mentioned before in our articles that companies use the terms <a href=\"https:\/\/www.thesslstore.com\/blog\/the-real-truth-about-tls-vs-ssl-the-difference-may-surprise-you\/\">SSL and TLS<\/a> interchangeably even though they\u2019re technically different? Yeah, that same line of thinking applies here.)<\/p>\n\n\n<span style=\"display:none\" class=\"tl-placeholder-f-type-shortcode_15135\"><\/span>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-does-a-key-management-service-do\">What Does a Key Management Service Do?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A KMS is a form of secrets management that helps you manage keys and their meta data. It can deploy on-prem or in the cloud (depending on your chosen platform and vendor). The goal of using one of these systems is to help you keep all of your cryptographic keys as secure as possible. It does this in several ways (depending on which KMS you use):<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Creating secure keys that protect your data.<\/strong> A great KMS enables you to generate keys that have sufficient entropy (randomness). Every key is a string of hexadecimal characters \u2014 the more random the order, the harder it is to crack. &nbsp;<\/li>\n\n\n\n<li><strong>Giving you visibility to view and monitor keys.<\/strong> A KMS is a tool that enables you to discover any key within your environment \u2014 even those not created in the KMS. If you know what keys you have and where they\u2019re deployed, then you\u2019ll be able to properly manage them. (No more rogue keys!)<\/li>\n\n\n\n<li><strong>Allowing you to set permissions.<\/strong> Effective key management entails knowing who has access to which keys and why they\u2019re using them.<\/li>\n\n\n\n<li><strong>Helping you securely store your keys. <\/strong>Secure key storage is a critical component of virtually every KMS, which is why many of these systems use hardware security modules (HSMs) \u2014 more on that shortly. If you don\u2019t store your keys securely, they could become lost or stolen, which can result in data compromise.<\/li>\n\n\n\n<li><strong>Enabling you to use keys without needing direct access to them. <\/strong>Some key management services enable you to use your keys to digitally sign data without requiring access to the plaintext keys.<\/li>\n\n\n\n<li><strong>Providing you with a way to back up and archive keys. <\/strong>Rather than trying to handle key backups and escrows one a one-by-one basis, you can automate the process.<\/li>\n\n\n\n<li><strong>Allowing you to automatically rotate SSH keys.<\/strong> Some key management systems offer automation. This means you can automatically rotate your SSH keys for increased security on web servers.<\/li>\n\n\n\n<li><strong>Enabling you to import existing keys. <\/strong>Some key management services enable you to bring your own keys (BYOK) by importing them from your computers, servers, devices, and\/or on-prem HSM to their cloud environment.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/csrc.nist.gov\/Projects\/key-management\/publications\">National Institute of Standards and Technology<\/a> says that while keys can be managed manually, some circumstances may require the use of an automated system (i.e., key management system).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-protecting-your-keys-is-essential-to-pki-security\">Protecting Your Keys Is Essential to PKI Security<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Practicing good key management is integral to the security and usefulness of your organization\u2019s <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-pki-a-crash-course-on-public-key-infrastructure-pki\/\">public key infrastructure<\/a>. PKI is, basically, the backbone of online security. PKI relies on cryptographic tools known as digital certificates and keys, which allow you to do everything from verifying your identity during logins to protecting your customers\u2019 data in transit as it leaves their browser and transmits to your web server.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As such, cryptographic keys exist throughout your network and larger IT environment. They often operate in the background, unseen by your customers by offering them security all the same. These tools help you facilitate secure authentication and data encryption.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Of course, we\u2019re not going to go into all of the technical details of PKI here as the topic is a bit of a rabbit hole and will take us off-track from the topic at hand. So, be sure to check out these two articles to learn more about <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-pki-a-crash-course-on-public-key-infrastructure-pki\/\">what PKI is<\/a> and <a href=\"https:\/\/www.thesslstore.com\/blog\/how-pki-works\/\">how PKI works<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-effective-key-management-matters-more-than-encryption\">Effective Key Management Matters More Than Encryption<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Wait, what? We\u2019re a company that lives and breathes everything encryption \u2014 why are we saying that something\u2019s more important? Well, if you don\u2019t properly manage your keys, then using those keys to encrypt your data won\u2019t do you any good.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Encrypting data with compromised keys is a pointless endeavor \u2014 bad guys can just use the compromised asset to decrypt your data. Using a compromised key for encryption is the equivalent of using a lightweight puzzle box to secure your most valuable possession. Sure, someone might try to go to the trouble of trying to crack the code to open the box. But the savvy criminal will simply break the box to gain access to its contents more quickly.<\/p>\n\n\n<span style=\"--tl-form-height-m:937.938px;--tl-form-height-t:1002.97px;--tl-form-height-d:1002.97px;\" class=\"tl-placeholder-f-type-shortcode_16294 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-s-the-difference-between-a-kms-and-an-hsm\">What\u2019s the Difference Between a KMS and an HSM?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">People often confuse HSMs with key management services. And while they\u2019re related, they\u2019re still separate in terms of their individual functionalities. Here\u2019s a quick summary of the differences between a KMS and an HSM:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-hardware-security-modules\">Hardware Security Modules<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-a-hardware-security-module-hsms-explained\/\">hardware security module<\/a> is typically a physical piece of hardware that handles key storage and cryptographic functions at scale. (There are some cloud HSMs available as well but the term HSM typically refers to the physical devices.) An HSM is a secure environment that allows you to handle key lifecycle management operations and offload many cryptographic operations as well. (This way, you\u2019re not overburdening your servers and other systems.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">HSMs can be stored as online or offline devices (depending on how you choose to use them). For example, public <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-a-certificate-authority-ca-and-what-do-they-do\/\">certificate authorities<\/a> use offline HSMs to store their root CAs to keep them as secure as possible. But some companies use online HSMs to store their private PKI\u2019s intermediate CA keys.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">HSM devices typically are offered with one of several Federal Information Processing Standards (FIPS) certified ratings from level 1 to level 4 (with 4 being the highest). The HSMs that many key management systems rely on are typically rated at FIPS 140-2 level 2 or better.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-key-management-systems\">Key Management Systems<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A key management system is typically a cloud-based tool for securing, generating and managing keys. This system enables users to handle everything relating to managing key lifecycles. This is a good option for organizations that don\u2019t require an on-prem HSM device or don\u2019t want to deal with having to protect it within their environment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, it\u2019s important to note that many key management services use HSMs on their backends to provide secure storage and backups. They also typically enable you to carry out limited cryptographic operations as well. &nbsp;For example, some key management systems will allow you to use the keys inside the KMS to perform data signing and other related functions.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"937\" height=\"738\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/relationship-kms-hsm.png\" alt=\"An illustration of the relationship between a key management service and a hardware security module\" class=\"wp-image-15120\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/relationship-kms-hsm.png 937w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/relationship-kms-hsm-300x236.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/relationship-kms-hsm-768x605.png 768w\" sizes=\"auto, (max-width: 937px) 100vw, 937px\" \/><figcaption class=\"wp-element-caption\">A basic illustration that shows the relationship between a key management service (KMS) and a hardware security module (HSM). <\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-6-reasons-why-using-a-key-management-service-can-benefit-your-business\">6 Reasons Why Using a Key Management Service Can Benefit Your Business<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Now we know both meanings of \u201cKMS\u201d and how HSMs play a role in key management, it\u2019s time to explore several reasons why a key management service matters to your business.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-1-using-a-key-management-system-helps-you-achieve-and-maintain-compliance\">1.&nbsp;Using a Key Management System Helps You Achieve and Maintain Compliance<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Compliance is essential. Whether your business falls in the healthcare sector or you\u2019re an ecommerce business that accepts online credit card payments, remaining compliant with regulations and laws is non-negotiable \u2014 you have to do it if you want to keep your doors open.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But compliance isn\u2019t a one-and-done kind of thing; it requires ongoing efforts, audits, and other security processes to prove you\u2019re doing what you\u2019re supposed to do in terms of securing sensitive data. A crucial part of this is keeping your keys secure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s emphasize this point for the people who might be skimming this article: <strong>cryptographic keys are only useful if you keep them safe.<\/strong> This means preventing unauthorized users from accessing or using them. If someone gets their hands on your private keys (digitally speaking, of course), they can gain access to whatever those keys can touch.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Needless to say, regulators and customers won\u2019t be happy for reasons we\u2019ll discuss in section five. But in the meantime, let\u2019s continue to explore how key management services help your organization and protect your customers\u2019 data. &nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-2-implementing-a-kms-keeps-your-data-and-systems-secure\">2.&nbsp;Implementing a KMS Keeps Your Data and Systems Secure<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019re pretty sure we don\u2019t need to explain why it\u2019s important to secure your data. If you\u2019re like most organizations, the fact of the matter is that you have cryptographic keys in use across all of your IT environments, including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Virtual environments and testing servers,<\/li>\n\n\n\n<li>Email servers, file servers and databases,<\/li>\n\n\n\n<li>Website and web apps, and<\/li>\n\n\n\n<li>Private and public clouds.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">As such, a key management service can help you secure your files and communications both while they\u2019re in transit and at rest.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-3-relying-on-a-key-management-system-helps-you-prevent-unauthorized-access\">3.&nbsp;Relying on a Key Management System Helps You Prevent Unauthorized Access<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Another benefit of effective key management is that it helps you ensure that only the right people have access to secure resources. KMS tools typically enable you to define permissions for how and where keys are used. If someone doesn\u2019t have the right key, they can\u2019t use an authentication certificate to verify their identity or decrypt encrypted information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Properly managing your keys is integral to <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-digital-identity-why-does-it-matter\/\">digital identity<\/a> and secure device and user authentication \u2014 both of which help you keep data secure from prying eyes.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-4-ensuring-you-always-have-access-to-your-server-data\">4.&nbsp;Ensuring You Always Have Access to Your Server &amp; Data<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Effective key management helps you avoid the hassle, frustration, and other issues that stem from losing cryptographic keys. Imagine the following scenario: You have a great developer working for your company. They create a server, which they use a single SSH key pair to access. But what happens when they leave the company a few weeks later and your access to that server disappears with them? Nothing good, we can tell you.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Depending on the specific situation, this could spell disaster for your business. Losing even a single SSH key to a server means that you might not be able to access the server again in the future. Simply put, there aren\u2019t locksmiths for SSH keys. So, you need to ensure that you have key management processes, policies and technologies in place to prevent this type of situation from occurring.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-5-adopting-a-kms-as-part-of-your-key-management-strategy-increases-efficiency\">5.&nbsp;Adopting a KMS as Part of Your Key Management Strategy Increases Efficiency<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Implementing a key management service can help you streamline your organization\u2019s key management tasks. Rather than having to dedicate part of your IT team to handle everything relating to key lifecycle management tasks \u2014 generating, deploying, using, managing, and destroying keys \u2014 you can free up these personnel assets to focus on other critical functions. &nbsp;&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-6-implementing-a-key-management-service-helps-you-mitigate-costs\">6.&nbsp;Implementing a Key Management Service Helps You Mitigate Costs<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Manually managing your keys can be a nightmare. It costs loads of money in terms of time, IT resource investments, and employing knowledgeable and skilled personnel. This can run up a high tab in no time.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Furthermore, manually managing your keys is a poor key management practice because it can result in one or more keys falling by the wayside and increase your attack surface as a shadow IT asset. As you can imagine, this can result in a litany of direct and indirect costs:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Non-compliance fines and penalties,<\/li>\n\n\n\n<li>Harm to your brand and reputation,<\/li>\n\n\n\n<li>Damaged customer relationships,<\/li>\n\n\n\n<li>Lost revenue and future sales opportunities,<\/li>\n\n\n\n<li>Costs associated with responding to and recovering from a data breach,<\/li>\n\n\n\n<li>Costs associated with informing customers about any security incidents your mitigation strategy,<\/li>\n\n\n\n<li>Other financial consequences such as lawsuits and settlements.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-final-takeaways-on-the-importance-of-key-management-services\">Final Takeaways on the Importance of Key Management Services<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Alright, you\u2019ve stuck with us this long. Now, it\u2019s time to drive home the biggest point of all. Whether you\u2019re looking to use a key management tool to manage your keys in-house or you opt to work with a key management service provider, the important thing is to ensure you\u2019re properly managing your cryptographic key lifecycles.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Poor key management reflects negatively on your brand and results in far-reaching financial damages. As such, it\u2019s important that you take the time now to assess your organization\u2019s existing key management practices and tools to ensure you have your ducks in a row. Here are a few related resources that we think you\u2019ll find beneficial:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/pki-management-private-key-certificate-lifecycle-management-best-practices\/\">PKI Management: Private Key &amp; Certificate Lifecycle Best Practices<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/14-ssh-key-management-best-practices-you-need-to-know\/\">14 SSH Key Management Best Practices You Need to Know<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/12-enterprise-encryption-key-management-best-practices\/\">12 Enterprise Encryption Key Management Best Practices<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/csrc.nist.gov\/Projects\/key-management\/publications\">NIST Key Management<\/a> resources page<\/li>\n<\/ul>\n\n\n<span style=\"--tl-form-height-m:801.312px;--tl-form-height-t:638.344px;--tl-form-height-d:638.344px;\" class=\"tl-placeholder-f-type-shortcode_12763 tl-preload-form\"><span><\/span><\/span>","protected":false},"excerpt":{"rendered":"<p>A lost or stolen cryptographic key can devastate a company \u2014 that\u2019s why many companies choose to use key management services to protect and secure their organization\u2019s sensitive assets When&#8230;<\/p>\n","protected":false},"author":17,"featured_media":15124,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[16,10200],"tags":[10035,13141,13142],"class_list":["post-15118","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hashing-out-cyber-security","category-monthly-digest","tag-key-management","tag-key-management-service","tag-kms","post-with-tags"],"views":18410,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/key-management-service-feature.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/15118","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=15118"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/15118\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/15124"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=15118"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=15118"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=15118"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}